Ox2A Security Blog
Testing Windows Defender and Wazuh with Atomic Red Team Posted on septemper, 28 by Zehra Begum Introduction Building my first SIEM deployment hands-on cybersecurity journey with log aggregation, network visibility, and threat detection. I cover how I stood up and modified a baseline SIEM environment, encountered a few real-world misconfigurations along the way, and ran attack commands using…
Zehra Begum, a cybersecurity specialist in network security and threat detection, shared her first contribution to the cybersecurity community in her testing of Windows Defender and Wazuh with Atomic Red Team. The post focused on how she built and modified a baseline SIEM environment, encountered misconfigurations, and ran attack commands using ART to observe the results in logs.
In the setup, Zehra configured log shipping agents and adjusted system files to capture enhanced host and network telemetry. The experiments included testing SIEM detection against various persistence techniques, such as scheduled tasks (T1053.005), obfuscated files or information registry modifications (T1027), and valid accounts (T1078).
The experiments revealed the direct link between endpoint configuration and SIEM visibility, emphasizing the importance of proper log verbosity. To prevent similar issues, Zehra advised validating configuration syntax and service status, ensuring host-level auditing policies are correctly enabled for process execution and command-line arguments.
Zehra concluded that the most valuable lesson was observing raw adversary actions executed via Atomic Red Team, instantly transforming into structured alerts and log fields inside the SIEM dashboard. She encouraged aspiring analysts not to panic if logs don't appear immediately, and to systematically isolate the path from event creation to SIEM ingestion.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.